|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure a custom attribute, see here |
||
|
SP-side Configuration |
|
Configured by the administrator |
| 〇 |
Request configuration from the SP |
|
|
Provisioning |
API-based provisioning supported (account management possible in TrustLogin) |
|
|
SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
〇 |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
〇 |
Android - Native App |
|
Note: For the iOS and Android native apps, you need to scan the dedicated QR code while the app is installed.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "zaico (SAML)".
- Download the metadata using the "Download Metadata" button under "Identity Provider Information".
Now, switch to configuring zaico.
Do not click the "Register" button yet — open zaico in a separate window.
zaico Settings
- Log in to zaico and open "Settings > Feature Settings".
- For "SAML Authentication", select "Enable".
- Configure the "SAML Authentication" settings as follows.
Entity ID Note down using the copy button Assertion Consumer Service URL Note down using the copy button Federation Metadata XML Upload the metadata you noted down from TrustLogin
- After uploading the metadata, the SAML information will be reflected. Click the "Apply" button to submit the SAML settings for approval.
- In "Other Settings", you can configure the login session. After logging in via SSO, you will be automatically logged out of zaico once the number of seconds set here has elapsed. Configure as needed and click "Update".
- Once ZAICO Inc. has finished configuring the metadata, you will receive an email indicating whether the request was approved.
- Once the SAML settings are approved, the "SAML Authentication" settings screen will display a "Dedicated Login URL" and a "Mobile QR Code" for use with the mobile app. Copy the "Dedicated Login URL" and note it down.
Note: The "Dedicated Login URL" and "Mobile QR Code" can also be found in the approval email from ZAICO Inc.
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure the "Service Provider Settings" as follows.
Login URL The "Dedicated Login URL" you noted down from zaico Entity ID The "Entity ID" you noted down from zaico ACS URL for the Service The "Assertion Consumer Service URL" you noted down from zaico
- Click the "Register" button to save.
Return to zaico again.
zaico Settings (Continued)
- In zaico, open "User Management > User List / Add" and select the user(s) to switch to SAML authentication login.
- For "Authentication Method", click "Change to SAML Authentication".
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "zaico (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
② When an administrator adds members
- Search for and click the "zaico (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
Login Method
Running "zaico (SAML)" from My Page or the browser extension will take you to the zaico SSO login screen.
Click the "Log in with SSO" button to log in.
Native App Login Method
For the iOS and Android native apps, you need to scan the dedicated QR code while the zaico app is installed. Please note that scanning the QR code without the app installed will not allow you to log in.
On a device with the native app installed, scan the QR code from either the zaico SAML authentication screen, the user information screen, or the approval email from ZAICO Inc.
[SAML Authentication Screen]
[User Information Screen]
Scanning the QR code will display the SSO login screen shown below. Clicking "Log in with SSO" will allow you to log in via SAML authentication.